long-task
Warn
Audited by Socket on May 13, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s capabilities mostly match its stated purpose as a long-running project orchestrator, and there is no clear credential theft or exfiltration path. The main issue is proportionality: it normalizes sustained autonomous coding, command execution, merging, and continuation without per-action user approval, which makes it high risk operationally even though it does not appear malicious.
Confidence: 86%Severity: 74%
Audit Metadata